The Central Log Server must be configured to use internal system clocks to generate time stamps for log records.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-206457 | SRG-APP-000116-AU-000270 | SV-206457r960927_rule | CCI-000159 | low |
| Description | ||||
| Without an internal clock used as the reference for the time stored on each event to provide a trusted common reference for the time, forensic analysis would be impeded. Determining the correct time a particular event occurred on a system is critical when conducting forensic analysis and investigating system events. If the internal clock is not used, the system may not be able to provide time stamps for log messages. Additionally, externally generated time stamps may not be accurate. Applications can use the capability of an operating system or purpose-built module for this purpose. | ||||
| STIG | Date | |||
| Central Log Server Security Requirements Guide | 2024-12-04 | |||
Related Frameworks
3 paths across 3 frameworks
Related Frameworks
NIST 800-531 mapping
AU-8
1.00
- DISA · 3 · disa_xccdf · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
NIST 800-1711 mapping
3.3.7
1.00
- DISA · 3 · disa_xccdf · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI1 mapping
CCI-000159
1.00
- DISA · 3 · disa_xccdf · related
Details
Check Text (C-206457r960927_chk)
Examine the configuration.
Verify the Central Log Server uses internal system clocks to generate time stamps for log records.
If the Central Log Server is not configured to use internal system clocks to generate time stamps for log records, this is a finding.
Fix Text (F-6717r285616_fix)
Configure the Central Log Server to use internal system clocks to generate time stamps for log records.